SecurityBrief Ireland - Technology news for CISOs & cybersecurity decision-makers
Ireland
Genetec urges buyers to test vendors for CRA readiness

Genetec urges buyers to test vendors for CRA readiness

Thu, 10th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Genetec has issued guidance for security leaders on assessing whether technology providers are ready for the EU Cyber Resilience Act, as the regulation's vulnerability-reporting obligations take effect.

The law will reshape expectations for makers of connected products sold in the European Union and will also affect organisations that distribute, install, procure and operate connected security devices.

At the centre of the guidance are five questions buyers of physical security technology should ask suppliers when reviewing product security, transparency and long-term support. They cover the length of security update commitments, whether cybersecurity was built into products from the outset, how vulnerabilities are handled, how open providers are about their practices, and how they support customers after deployment.

The regulation sets cybersecurity requirements for products with digital elements, with greater emphasis on secure development, vulnerability management, transparency and ongoing support throughout a product's lifecycle. That means procurement teams and security managers may need to look beyond headline features and examine how vendors manage cyber risk after systems are installed.

Five questions

The first issue Genetec highlights is how long a product will receive security updates and support. Buyers should ask providers how long updates will be delivered, how vulnerabilities will be addressed, and what support will be available when products reach end of life.

Under the rules, manufacturers must provide security updates and vulnerability handling for at least five years, making support periods a more prominent factor in purchasing decisions.

The second question is whether cybersecurity was built into the product from the beginning. Secure by Design and Secure by Default are central to the new framework and should be reflected in design, development, testing and ongoing maintenance.

The third area is vulnerability management. Buyers are advised to look for an established programme covering regular security testing, a coordinated vulnerability disclosure policy, risk-based remediation without undue delay, secure delivery of updates, and clear advisories on resolved issues.

The fourth question concerns transparency. Providers should explain how they develop, test and maintain products, and give customers and integrators guidance on secure deployment, system hardening, vulnerabilities and updates.

The final question is how providers support long-term cyber resilience. That includes how they determine and communicate support periods, handle vulnerabilities, deliver updates, support secure operation and manage product retirement, as well as what evidence they can provide that products meet applicable cybersecurity requirements throughout their lifecycle.

Wider impact

Although the legislation is aimed mainly at manufacturers, the compliance burden is likely to spread across the physical security supply chain. Integrators, resellers and end users may need more detailed product documentation and clearer commitments from suppliers as they review purchasing, deployment and maintenance decisions.

Physical security systems have become increasingly connected, linking cameras, access control devices, intercoms and other equipment to wider corporate networks. That has raised the importance of patching, vulnerability disclosure and support planning in a sector once judged primarily on hardware performance and operational reliability.

Mathieu Chevalier, Principal Security Architect at Genetec, said the new rules reinforce existing security principles. "The Cyber Resilience Act reinforces many of the secure-by-design and lifecycle management principles that Genetec has been advocating for years," Chevalier said.

He said the regulation also gives customers a clearer basis for vendor assessment. "By raising expectations for product security and transparency, the CRA regulations give buyers a clear basis for evaluating technology providers and the long-term cyber resilience of their products," Chevalier said.

Procurement shift

The guidance points to a broader shift in how buyers may need to assess physical security technology. Instead of treating cybersecurity as a technical add-on or a post-installation task, organisations are being encouraged to make it part of supplier due diligence, contract review and lifecycle planning.

For large estates running connected surveillance and access systems across multiple sites, that could mean closer scrutiny of vendor disclosure processes, patching timetables and end-of-life policies. It may also increase pressure on suppliers to show that product security is documented and maintained over several years.

Chevalier said organisations should treat cyber risk as a continuing relationship with suppliers rather than a one-off purchase decision. "Organisations best positioned to manage future cyber threats treat cybersecurity as an ongoing partnership, not a one-time procurement decision," Chevalier said. "The CRA helps reinforce that approach by setting common expectations for transparency, disciplined vulnerability management, and long-term product support, benefiting manufacturers, integrators and the organisations that depend on connected physical security systems."